CVE-2026-84382CWE-409

CVE-2026-84382

High · published September 2, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
28.0
In the wild
Unconfirmed
What it is

HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bounded pieces to the application. A 64 KiB compressed chunk can expand to approximately 64 MiB in one intermediate allocation, so an attacker-controlled or compromised server can cause severe memory pressure or out-of-memory process termination even when the application streams the response. This issue is fixed in version 2.12.0.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00350 · 28.0th percentile
Weakness
CWE-409 · Improper Handling of Highly Compressed Data (Data Amplification)
Published
2026-09-02T23:18Z
References (4)
EPSS history
Timeline
  • 04 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 02 SEP 18:03Z
    HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
    cvelistv5